Impact
The vulnerability is a classic CSRF flaw that allows an attacker to manipulate router settings through a victim administrator, potentially disrupting device functionality. The flaw carries no confidentiality impact as data interception is not enabled, but it can undermine integrity of router configuration and availability of the device by altering key network parameters. The weakness corresponds to CWE-352, showing a failure in ensuring request authenticity.
Affected Systems
Affected models include the NETGEAR XR1000, XR1000v2, and XR500 gaming routers. The patch version for XR1000 and XR1000v2 is V1.1.0.22. The XR500 is marked end‑of‑support, so no security updates are expected beyond its current release.
Risk and Exploitability
The CVSS score of 1.8 indicates a low severity. With an EPSS score of 0.00119, equivalent to less than 1%, the likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is social engineering, where an attacker tricks an administrator into submitting a malicious request, as no remote network‑level exploitation path is described.
OpenCVE Enrichment